{"id":73,"date":"2015-05-12T08:36:43","date_gmt":"2015-05-12T08:36:43","guid":{"rendered":"http:\/\/www.smtp-server.net\/?p=73"},"modified":"2015-05-04T20:34:51","modified_gmt":"2015-05-04T20:34:51","slug":"auth-smtp-easy-steps-to-stop-smtp-auth-relay-attack-and-identify-compromised-email-account-for-postfix","status":"publish","type":"post","link":"https:\/\/www.smtp-server.net\/hu\/auth-smtp-easy-steps-to-stop-smtp-auth-relay-attack-and-identify-compromised-email-account-for-postfix\/","title":{"rendered":"Auth SMTP - Egyszer\u0171 l\u00e9p\u00e9sek az SMTP AUTH Relay t\u00e1mad\u00e1s meg\u00e1ll\u00edt\u00e1s\u00e1hoz \u00e9s a Postfix kompromitt\u00e1lt e-mail fi\u00f3kj\u00e1nak azonos\u00edt\u00e1s\u00e1hoz"},"content":{"rendered":"<div style=\"float:left\">https:\/\/youtube.com\/watch?v=IaGV9l_3xZM<\/div>\n<p>Ma m\u00e1r sok e-mail alkalmaz\u00e1st, p\u00e9ld\u00e1ul a Sendmailt, a Postfixet vagy ak\u00e1r az MS Exchange-et is \u00fagy tervezt\u00e9k \u00e1t, hogy cs\u00f6kkents\u00e9k annak lehet\u0151s\u00e9g\u00e9t, hogy \u2018spam-relay\u2019-v\u00e9 v\u00e1ljanak. Tapasztalataink szerint a legt\u00f6bb SMTP AUTH relay t\u00e1mad\u00e1st a gyeng\u00e9n jelsz\u00f3val v\u00e9dett felhaszn\u00e1l\u00f3i fi\u00f3kok felt\u00f6r\u00e9se okozza. Ha a fi\u00f3kokat felfedezt\u00e9k \u00e9s felt\u00f6rt\u00e9k. Spammer hiteles\u00edti a felhaszn\u00e1l\u00f3i hiteles\u00edt\u0151 adatokkal, akkor kapnak enged\u00e9lyt a szerveren kereszt\u00fcl t\u00f6rt\u00e9n\u0151 tov\u00e1bb\u00edt\u00e1sra, amelyet azt\u00e1n spamek k\u00fcld\u00e9s\u00e9re haszn\u00e1lnak.<\/p>\n<p><!--more--><\/p>\n<p>Below are the easy steps to stop these spam emails quickly and identify which account(s) has been compromised.<\/p>\n<p><strong>Step1: Stop on on-hold mail queue<\/strong>.<\/p>\n<p>Large amount of spam emails keep queueing your mail spool. What even worst is all the spam it fill up all your \/var. Thus, it is always to hold the mail queue for temporary until you find out the which account has been exploited by spammer and send a large amount of emails.<\/p>\n<p><strong>Step2: Check your mail log.<\/strong><\/p>\n<p>Go to \/var\/log\/maillog to have a quick look on the line with from:. You might see lots of email domain name there are not belong yo your organization. This is due to the spammer is faking the mail from:.<\/p>\n<p><strong>Step 3: Identify compromised account authenticating SMTP AUTH connection<\/strong><\/p>\n<p>Next, let us check those email accounts that has been exploited. Run a have cat grep sasl_username and sort it. You should see a long list of the login attempt and session for those exploited account. You can also do a quick calculation by running wc -l command to see total sessions for a particular user.<\/p>\n<p><strong>Step4: Disable the exploited email account.<\/strong><\/p>\n<p>Once, we have SASL_username string, which is the user account. You are advised to disabled or change the password to complex password.<\/p>\n<p><strong>Step 5: Move the mail queue or delete the spam email<\/strong><\/p>\n<p>Now, we have to deal with our mail queue. Easier and fastest way is to move your mail queue and do the housekeeping later. Or, you can delete those spam email using Bash script.<\/p>\n<p><strong>Step 6: Release Mail queue<\/strong><\/p>\n<p>Remember to release mail queue after our housekeeping process and keep on monitoring of the mail traffic.<\/p>","protected":false},"excerpt":{"rendered":"<p>Today lots of the email application such as Sendmail, Postfix, or even MS Exchange has been re-designed to reduce the possibility of become an &#8216;spam-relay&#8217;. From our experience, most of the SMTP AUTH relay attack is caused by the compromised of the weakly password protected user accounts. Once the accounts discovered and been compromised. Spammer <a href=\"https:\/\/www.smtp-server.net\/hu\/auth-smtp-easy-steps-to-stop-smtp-auth-relay-attack-and-identify-compromised-email-account-for-postfix\/\" rel=\"nofollow\"><span class=\"sr-only\">Read more about Auth SMTP &#8211; Easy Steps to Stop SMTP AUTH Relay Attack and Identify Compromised Email Account for Postfix<\/span>[&hellip;]<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-73","post","type-post","status-publish","format-standard","hentry","category-smtp-servers"],"_links":{"self":[{"href":"https:\/\/www.smtp-server.net\/hu\/wp-json\/wp\/v2\/posts\/73","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.smtp-server.net\/hu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.smtp-server.net\/hu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.smtp-server.net\/hu\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.smtp-server.net\/hu\/wp-json\/wp\/v2\/comments?post=73"}],"version-history":[{"count":1,"href":"https:\/\/www.smtp-server.net\/hu\/wp-json\/wp\/v2\/posts\/73\/revisions"}],"predecessor-version":[{"id":74,"href":"https:\/\/www.smtp-server.net\/hu\/wp-json\/wp\/v2\/posts\/73\/revisions\/74"}],"wp:attachment":[{"href":"https:\/\/www.smtp-server.net\/hu\/wp-json\/wp\/v2\/media?parent=73"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.smtp-server.net\/hu\/wp-json\/wp\/v2\/categories?post=73"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.smtp-server.net\/hu\/wp-json\/wp\/v2\/tags?post=73"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}